May actually delete this account before the 15th of November if the new AI policy change will not be undone.
I'll instead be posting on the my Bluesky account for the foreseeable future.
https://t.co/vpVrGNYSeD
Hacking the #EU#AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid.
Other issues:
1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying.
2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step.
Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
@tyl0saur It creates a kind of uncannny valley effect where the work has kid-inappropriate elements but is still written like it’s for kids. So it’s not an adult show/novel/whatever, it’s one for kids with violence, sex, and swearing added.
Fuck Discord. I'm not going to continue using it if they're implementing the ID verification.
I urge everyone to leave as well. Do not idly submit to this ineffective slippery slope nonsense.
German Voice Actor association 'Verband Deutscher Sprecher' is boycotting NETFLIX
A clause in their new contracts allowed room for Netflix to use their voices for AI training without compensation
@CoeurDeLuciole also I don't know if Htz got harassed directly by anyone, I would not have expected that, though they've privated their profile.
In that case I'd wanna apologize to Htz personally. I really did not think anything would happen that would affect them
@CoeurDeLuciole I don't think it was really dogpiling, nor bullying. It was like 4 people just laughing at someone making a hate video on fezezen and another weird video in a vacuum.
As in a brief laugh and forget in a few hours. I think that's what most people would think if they saw the logs.
@CoeurDeLuciole You have a point with the contributor part. I never saw myself as a figure. I mainly sit on the side, with barely any insight or input on the game. I just draw occasionally, so I never really consider stepping in regarding moderation.
May actually delete this account before the 15th of November if the new AI policy change will not be undone.
I'll instead be posting on the my Bluesky account for the foreseeable future.
https://t.co/vpVrGNYSeD